SV-239304r674841_rule
V-239304
SRG-OS-000423-VMM-001700
ESXI-67-000049
CAT II
10
From the vSphere Client, select the ESXi host and go to Configure >> Networking >> VMkernel adapters.
Select the Management VMkernel and click "Edit".
On the Port properties tab, uncheck everything but "Management.”
On the IP Settings tab, enter the appropriate IP address and subnet information and click "OK".
Set the appropriate VLAN ID >> Configure >> Networking >> Virtual switches.
Select the Management portgroup and click "Edit".
On the properties tab, enter the appropriate VLAN ID and click "OK".
Verify the Management VMkernel port group is on a dedicated VLAN, which can be on a common standard or distributed virtual switch as long as the Management VLAN is not shared by any other function and is not accessible to anything other than management-related functions such as vCenter.
The check for this will be unique per environment.
From the vSphere Client, select the ESXi host and go to Configure >> Networking.
Review the VLAN associated with the Management VMkernel and verify it is dedicated for that purpose and is logically separated from other functions.
If the network segment is accessible, except to networks where other management-related entities such as vCenter are located, this is a finding.
V-239304
False
ESXI-67-000049
Verify the Management VMkernel port group is on a dedicated VLAN, which can be on a common standard or distributed virtual switch as long as the Management VLAN is not shared by any other function and is not accessible to anything other than management-related functions such as vCenter.
The check for this will be unique per environment.
From the vSphere Client, select the ESXi host and go to Configure >> Networking.
Review the VLAN associated with the Management VMkernel and verify it is dedicated for that purpose and is logically separated from other functions.
If the network segment is accessible, except to networks where other management-related entities such as vCenter are located, this is a finding.
M
5326